NIH IT Security Contract Provisions_ Mutation Analysis Off0Site Laboratory Testing.pdf

PDF 287 KB Posted

Attached to
Mutation Analysis Laboratory Services Federal contract opportunity
Solicitation number
11-000872
Issued by
Department of Health and Human Services National Institutes of Health

About this file

NIH Security Provisions

View the file

Other files for this federal contract opportunity

Other files attached to Mutation Analysis Laboratory Services, newest first.
File Type Posted
Mutation Analysis Schedule I.pdf PDF
Mutation Analysis Schedule III.pdf PDF
Mutation Analysis Schedule II.docx DOCX document
SOW mutation analysis 012511.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CC SECURITY – IT CONTRACT PROVISIONS

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 1

FEDERAL INFORMATION AND INFORMATION SYSTEMS SECURITY:

Include when contractor/subcontractor personnel will (1) develop, (2) have the ability to access, or

(3) host and/or maintain Federal information and/or Federal information systems(s). For additional information see:

For more information, see HHS Information Security Program Policy at:

http://intranet.hhs.gov/infosec/index.html

HHS Contractor Oversight Guide at:

http://intranet.hhs.gov/infosec/docs/policies_guides/COG/co_guide_toc.htm

PERSONALLY IDENTIFIABLE INFORMATION (PII):

Include when contractor/subcontractor personnel will have access to, or use of, Personally

Identifiable Information (PII), including instances of remote access to or physical removal of such information beyond agency premises or control. For additional information, see:

OMB Memorandum M-06-15, Safeguarding Personally Identifiable

Information (05-22-06): http://www.whitehouse.gov/omb/memoranda/fy2006/m-06-15.pdf

OMB Memorandum M-06-16, Protection of Sensitive Agency Information (06-23-06):

http://www.whitehouse.gov/OMB/memoranda/fy2006/m06-16.pdf

OMB Memorandum M-06-19, Safeguarding Against and Responding to the Breach of Personally

Identifiable Information: http://www.whitehouse.gov/omb/memoranda/fy2006/m06-19.pdf

Guide for Identifying Sensitive Information, including Information in Identifiable Form, http://ocio.nih.gov/security/NIH_Sensitive_Info_Guide.doc

NIH INFORMATION AND PHYSICAL ACCESS SECURITY:

This acquisition requires the Contractor to:

develop, have the ability to access or host and/or maintain Federal information and/or Federal information systems(s).

http://intranet.hhs.gov/infosec/index.html http://intranet.hhs.gov/infosec/docs/policies_guides/COG/co_guide_toc.htm http://www.whitehouse.gov/omb/memoranda/fy2006/m-06-15.pdf http://www.whitehouse.gov/OMB/memoranda/fy2006/m06-16.pdf http://www.whitehouse.gov/omb/memoranda/fy2006/m06-19.pdf http://ocio.nih.gov/security/NIH_Sensitive_Info_Guide.doc

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 2 access, or use, Personally Identifiable Information (PII), including instances of remote access to or physical removal of such information beyond agency premises or control.

The Contractor and all subcontractors performing under this acquisition shall comply with the following requirements: shall comply with the following requirements:

a. Federal Information Security Management Act of 2002 (FISMA), Title III, E-Government

Act of 2002, Pub. L. No. 107-347 (Dec. 17, 2002);

http://csrc.nist.gov/drivers/documents/FISMA-final.pdf

b. OMB Memorandum M-07-16, Protection of Sensitive Agency Information.

http://www.whitehouse.gov/omb/assets/omb/memoranda/fy2007/m07-16.pdf

c. Homeland Security Presidential Directive/HSPD-12, Policy for a Common Identification

Standard for Federal Employees and Contractors (08-27-04):

http://www.whitehouse.gov/news/releases/2004/08/print/20040827-8.html

d. OMB Memorandum M-05-24, Implementation of Homeland Security Presidential Directive

(HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and

Contractors (08-05-05): http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf

e. Federal Information Processing Standards Publication (FIPS PUB) 201-1 (Updated June 26, 2006): http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf

f. HHS Interim Policy: Contractual Implementation of Homeland Security Presidential

Directive (HSPD) 12, Policy for a Common Identification Standard for Federal Employees and Contractors [Draft]

A. INFORMATION TYPE

[ ] Administrative, Management and Support Information:

**** (NOTE: If the above box is checked, the specific type(s) of information from NIST SP 800-60, Volume II: Appendices to Guide for Mapping Types of

Information and Information Systems To Security Categories, APPENDIX C, Table 3, at http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf must be inserted here. This information will be provided by the IC

ISSO and/or Project Officer) ****

[ X] Mission Based Information:

D.14.4 HealthCare Delivery Services Information Type

B. SECURITY CATEGORIES AND LEVELS

http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://www.whitehouse.gov/omb/assets/omb/memoranda/fy2007/m07-16.pdf http://www.whitehouse.gov/news/releases/2004/08/print/20040827-8.html http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 3

**** (NOTE: Based on information provided by the ISSO and Project Officer, select the Security Level for each Security Category. Select the Overall Security Level which is the highest level of the three factors (Confidentiality, Integrity and Availability).

NIST SP 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendices C and D contain suggested

Security Levels for Each Information Type at

For additional information and assistance for completion of this item, see Table 1, Security Categorization of Federal Information and Information Systems at:

http://irm.cit.nih.gov/security/table1.htm )****

Confidentiality Level: [ ] Low [ X] Moderate [ ] High

Integrity Level: [ ] Low [ ] Moderate [ X] High

Availability Level: [ X Low [ ] Moderate [ ] High

Overall Level: [ ] Low [ ] Moderate [ X] High

C. POSITION SENSITIVITY DESIGNATIONS

1. The following position sensitivity designation(s) and associated suitability determination(s) and background investigation requirements apply to this acquisition.

**** (NOTE: Check all that apply. Additional Note: Levels 2, 3, and 4 are reserved for National Security positions which are generally not applicable to NIH. For additional information and assistance for completion of this item, see Table 2, Position Sensitivity Designations for Individuals Accessing Agency Information at:

http://irm.cit.nih.gov/security/table2.htm )****

[ ] Level 6: Public Trust -High Risk (Requires Suitability Determination with a BI).

Contractor/subcontractor employees assigned to a Level 6 position are subject to a

Background Investigation (BI).

[ X] Level 5: Public Trust - Moderate Risk (Requires Suitability Determination with

NACIC, MBI or BI). Contractor/subcontractor employees assigned to a Level 5 position with no previous investigation and approval shall undergo a National Agency

Check and Inquiry Investigation plus a Credit Check (NACIC), a Minimum

Background Investigation (MBI), or a Limited Background Investigation (LBI).

[ X] Level 1: Non Sensitive (Requires Suitability Determination with an NACI).

Contractor/subcontractor employees assigned to a Level 1 position are subject to a

National Agency Check and Inquiry Investigation (NACI).

http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf http://irm.cit.nih.gov/security/table1.htm http://irm.cit.nih.gov/security/table2.htm

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 4

2. The Contractor shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under this acquisition where the contractor will develop, have the ability to access, or host and/or maintain a federal information system(s). The roster shall be submitted to the Project Officer, with a copy to the Contracting Officer, within 14 calendar days of the effective date of this acquisition. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The Contracting Officer will notify the Contractor of the appropriate level of suitability investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at: http://ais.nci.nih.gov/forms/Suitability-roster.xls

Suitability Investigations are required for contractors who will need access to NIH information systems and/or to NIH physical space. However, contractors who do not need access to NIH physical space will not need an NIH ID Badge. Each contract employee needing a suitability investigation will be contacted via email by the NIH Office of

Personnel Security and Access Control (DPSAC) within 30 days. The DPSAC email message will contain instructions regarding fingerprinting as well as links to the electronic forms contract employees must complete.

Additional information can be found at the following website:

http://idbadge.nih.gov/background/index.asp

All contractor and subcontractor employees shall comply with the conditions established for their designated position sensitivity level prior to performing any work under this contract.

Contractors may begin work after the fingerprint check has been completed.

D. INFORMATION SECURITY TRAINING

Mandatory Training

All employees having access to (1) Federal information or a Federal information system or (2) personally identifiable information, shall complete the NIH Computer Security Awareness

Training and the NIH Privacy Awareness course at: http://irtsectraining.nih.gov/ before performing any work under this contract. Thereafter, employees having access to the information identified above shall complete an annual NIH- specified fiscal year refresher course during the life of this contract. The contractor shall also ensure subcontractor compliance with this training requirement.

Role-based Training.

http://ais.nci.nih.gov/forms/Suitability-roster.xls http://idbadge.nih.gov/background/index.asp http://irtsectraining.nih.gov/

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 5

HHS requires role-based training when responsibilities associated with a given role or position, could, upon execution, have the potential to adversely impact the security posture of one or more HHS systems. Read further guidance on Secure One HHS Memorandum on

Role-Based Training Requirement http://ocio.nih.gov/security/security-communicating.htm#RoleBased

The Contractor shall maintain a list of all information security training. Completed by each contractor/subcontractor employee working under this contract. The list shall be provided to the Project Officer and/or Contracting Officer upon request.

Information Security Awareness

FY Information Security Awareness Refresher

Privacy Awareness

Securing Remote Computers

E. RULES OF BEHAVIOR

The Contractor/subcontractor employees shall be required to comply with and sign the NIH

Information Technology General Rules of Behavior at:

http://irm.cit.nih.gov/security/nihitrob.html

F. PERSONNEL SECURITY RESPONSIBILITIES

(1) The Contractor shall notify the Contracting Officer, the Project Officer, and the Security

Investigation Reviewer within five working days before a new employee assumes a position that requires a suitability determination or when an employee with a security clearance stops working under the contract. The Government will initiate a background investigation on new employees requiring security clearances and will stop pending background investigations for employees that no longer work under the contract.

(2) The Contractor shall provide the Project Officer with the name, position title, e-mail address, and phone number of all new contract employees working under the contract and provide the name, position title and suitability determination level held by the former incumbent. If the employee is filling a new position, the Contractor shall provide a description of the position and the Government will determine the appropriate security level.

(3) The Contractor shall provide the Project Officer with the name, position title, and suitability determination level held by or pending for the departing employees.

http://ocio.nih.gov/security/security-communicating.htm#RoleBased http://irm.cit.nih.gov/security/nihitrob.html

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 6

Perform and document the actions identified in the "Employee Separation Checklist"

(http://ais.nci.nih.gov/forms/ITsecurity-seperation-checklist.rtf) when a

Contractor/Subcontractor employee terminates work under this contract. All documentation shall be made available to the Project Officer and/or Contracting Officer upon request.

G. (COMMITMENT TO PROTECT NON-PUBLIC DEPARTMENTAL INFORMATION

SYSTEMS AND DATA

1. Contractor Agreement

The Contractor and its subcontractors performing under this SOW shall not release, publish, or disclose non-public Departmental information to unauthorized personnel, and shall protect such information in accordance with provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of such information:

_18 U.S.C. 641 (Criminal Code: Public Money, Property or Records)

_18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information)

_Public Law 96-511 (Paperwork Reduction Act)

2. Contractor Employee Non-Disclosure Agreement

Each Contractor/subcontractor employee who may have access to non-public

Department information under this acquisition shall complete the Commitment to

Protect Non-Public Information – Contractor Employee Agreement A copy of each signed and witnessed Non-Disclosure agreement shall be submitted to the Project

Officer prior to performing any work under this acquisition.

Effective 12/13/2010, contractors listed in NED who have an AD account will be responsible to upload the original signed form or a copy, they need to scan it and upload it into the Training System at http://irtsectraining.nih.gov

3. System Interconnection Security Agreement (ISA) and Memorandum of Understanding

(MOU)

Systems that interconnect exchange or share sensitive information need to meet the

OMB A-130 requirement that "written management authorization (often in the form of a Memorandum of Understanding or Agreement,) be obtained prior to connecting with other systems and/or sharing sensitive data/information. The written authorization shall detail the rules of behavior and controls that must be maintained by the interconnecting systems." To meet this requirement it is required a System

Interconnection Security Agreement (ISA) and Memorandum of Understanding

(MOU) focused on protecting the data exchanged.

http://ais.nci.nih.gov/forms/ITsecurity-seperation-checklist.rtf http://irtsectraining.nih.gov/

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 7

An MOU and/or ISA will be required for any remote vendor access the NIHnet in order to ensure adequate security and the protection of the NIHnet.

NIH ISA Template NIH MOU Template

H. NIST SP 800-53 ASSESSMENT

This contract requires the Contractor to develop, host and/or maintain a Federal information system at the Contractor’s or any subcontractor’s facility. The Contractor shall submit an annual information security assessment using NIST SP 800-53 Recommended Security

Controls for Federal Information Systems. The assessment shall be due annually within 30 days after the anniversary date of the contract, with the final assessment due at contract completion. The assessments shall be based on the Federal IT Security Assessment

Framework and NIST SP 800-53 at:

NIST SP 800-53, Rev 3 http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf

Annex 1: Baseline Security controls for Low-Impact Information Systems http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex1_updated_may-

01-2010.pdf

Annex 2: Baseline Security controls for Moderate-Impact Information Systems http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex2_updated_may-

Annex 3: Baseline Security controls for High-Impact Information Systems http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex3_updated_may-

The Contractor shall ensure that all of its subcontractors (at all tiers), where applicable, comply with the above reporting requirements.

I. INFORMATION SYSTEM SECURITY PLAN (ISSP)

The SOW requires the Contractor to (1) develop a Federal information system at the

Contractor’s/subcontractor’s facility or (2) host or maintain a Federal information system at the Contractor’s/subcontractor’s facility.

http://ocio.nih.gov/nihsecurity/NIH_ISA_template.doc http://ocio.nih.gov/nihsecurity/NIH_MOU_template.doc http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex1_updated_may-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex1_updated_may-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex2_updated_may-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex2_updated_may-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex3_updated_may-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/800-53-rev3-Annex3_updated_may-01-2010.pdf

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 8

The Contractor's draft ISSP submitted with its proposal shall be finalized in coordination with the Project Officer no later than 90 calendar days after contract award.

Following approval of its draft ISSP, the Contractor shall update and resubmit its ISSP to the

Project Officer every three years or when a major modification has been made to its internal system. The Contractor shall use the current ISSP template in Appendix A of NIST SP 800-

18, Guide to Developing Security Plans for Federal Information Systems. (Located at http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf ). The details contained in the Contractor's ISSP shall be commensurate with the size and complexity of the requirements of the SOW based on the System Categorization determined above in subparagraph (b) Security Categories and Levels of this Article.

J. PERSONALLY IDENTIFIABLE INFORMATION (PII) SECURITY PLAN

The Offeror shall submit a PII Security Plan with its technical proposal that addresses each of the following items:

1. Verify the information categorization to ensure the identification of the PII requiring protection.

2. Verify the existing risk assessment.

3. Identify the Contractor’s existing internal corporate policy that addresses the information protection requirements of the SOW.

4. Verify the adequacy of the Contractor’s existing internal corporate policy that addresses the information protection requirements of the SOW.

5. Identify any revisions, or development, of an internal corporate policy to adequately address the information protection requirements of the SOW.

6. For PII to be physically transported to or stored at a remote site, verify that the security controls of NIST Special Publication 800-53 involving the encryption of transported information will be implemented.

http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf

7. When applicable, verify how the NIST Special Publication 800-53 security controls requiring authentication, virtual private network (VPN) connections will be implemented.

8. When applicable, verify how the NIST Special Publication 800-53 security controls enforcing allowed downloading of PII will be implemented.

9. Identify measures to ensure subcontractor compliance with safeguarding PII.

The details contained in the Offeror’s PII Security Plan must be commensurate with the size and complexity of the contract requirements based on the System Categorization specified above in the subparagraph entitled Security Categories and Levels. The Offeror’s PII

Security Plan will be evaluated by the Government for appropriateness and adequacy.

http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 9

**** (INCLUDE THE FOLLOWING WHEN THE CONTRACT REQUIRES THE

CONTRACTOR TO:

(1) DEVELOP A FEDERAL INFORMATION SYSTEM(S) AT THE

CONTRACTOR'S/SUBCONTRACTOR'S FACILITY,

OR

(2) HOST AND/OR MAINTAIN A FEDERAL INFORMATION SYSTEM(S) AT THE

CONTRACTOR'S/SUBCONTRACTOR'S FACILITY.

For additional information, see Table 3: Federal Information Security Safeguard Requirements

– Summary, at http://ocio.nih.gov/docs/public/table3.htm.)****

K. LOSS AND/OR DISCLOSURE OF PERSONALLY IDENTIFIABLE INFORMATION

(PII) – NOTIFICATION OF DATA BREACH

The Contractor shall be responsible for reporting all incidents involving the loss and/or disclosure of PII in electronic or physical form. Notification shall be made to the NIH

Incident Response Team IRT@mail.nih.gov via email within one hour of discovering the incident. The contractor shall follow-up with the IRT by completing and submitting one of the following two forms:

NIH PII Spillage Report [ http://irm.cit.nih.gov/security/PII_Spillage_Report.doc ]

NIH Lost or Stolen Assets Report [ http://irm.cit.nih.gov/security/Lost_or_Stolen.doc]

The notification requirements do not distinguish between suspected and confirmed breaches.

NIH Breach Notification

Remote storage of CC data is applicable to this acquisition.

In accordance with the Interim final rule about Breach Notification for Unsecured Protected

Health Information in Section 13402 of the Health Information Technology for Economic and

Clinical Health (HITECH) Act, published in the Federal Register on or about August 13, 2009.

1) The Clinical Center requires that all contractors/subcontractors with access to unsecured protected health information from CC Information Systems provide notice of a breach to the Clinical Center without unreasonable delay and in no case later than 60 days following the discovery of a breach.

http://ocio.nih.gov/docs/public/table3.htm mailto:IRT@mail.nih.gov http://irm.cit.nih.gov/security/PII_Spillage_Report.doc http://irm.cit.nih.gov/security/Lost_or_Stolen.doc

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 10

2) In the event of a breach, the Clinical Center requires that all contractors/subcontractors to the extent possible, provide the Clinical Center with the identification of each individual whose unsecured protected health information has been, or is reasonably believed to have been breached and any other information related to the breach. The required information must be provided when available but without unreasonable delay and within 60 days in order for the Government to provide notice to affected individuals.

L. DATA ENCRYPTION

The following encryption requirements apply to all laptop computers containing HHS data at rest and or HHS data in transit. The date by which the contractor shall be in compliance will be set by the Project Officer, however, device encryption shall occur before any sensitive data is stored on the laptop computer/mobile device, or within 45 days of the start of the contract, whichever occurs first.

1. The Contractor shall secure all laptop computers used on behalf of the government using a

Federal Information processing Standard (FIPS) 140-2 compliant whole-disk encryption solution. The cryptographic module used by an encryption or other cryptographic product must be tested and validated under the Cryptographic Module Validation Program / to confirm compliance with the requirements of FIPS PUB 140-2 (as amended). For additional information, refer to http://csrc.nist.gov/cryptval

2. The Contractor shall secure all mobile devices, including non-HHS laptops and portable media that contain sensitive HHS information by using a FIPS 140-2 compliant product.

Data at rest includes all HHS data regardless of where it is stored.

3. The Contractor shall use a FIPS 140-2 compliant key recovery mechanism so that encrypted information can be decrypted and accessed by authorized personnel. Use of encryption keys which are not recoverable by authorized personnel is prohibited. Key recovery is required by “OMB Guidance to Federal Agencies on Data Availability and

Encryption,” November 26, 2001, http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf.

Encryption key management shall comply with all HHS and NIH policies http://ocio.nih.gov/security/HHS_Encrypt_Policy_Guidance_Tools.html and shall provide adequate protection to prevent unauthorized decryption of the information.

All media used to store information shall be encrypted until it is sanitized or destroyed in accordance with NIH procedures. Contact the NIH Center for Information Technology for assistance http://cit.nih.gov/ServiceCatalog/Services.htm?Service=Media+Sanitization+Service

M. VULNERABILITY SCANNING REQUIREMENTS

http://csrc.nist.gov/cryptval http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf http://ocio.nih.gov/security/HHS_Encrypt_Policy_Guidance_Tools.html http://cit.nih.gov/ServiceCatalog/Services.htm?Service=Media+Sanitization+Service

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 11

This SOW requires the Contractor/subcontractor to host an NIH webpage or database. The

Contractor shall conduct periodic and special vulnerability scans, and install software/hardware patches and upgrades to protect automated federal information assets. The minimum requirement shall be to protect against vulnerabilities identified on the SANS Top-

20 Internet Security Attack Targets list ( http://www.sans.org/top20/?ref=3706#w1 ). The

Contractor shall report the results of these scans to the Project Officer on a monthly basis, with reports due 10 calendar days following the end of each reporting period. The Contractor shall ensure that all of its subcontractors (at all tiers), where applicable, comply with the above requirements.

N. Using Secure Computers to Access Federal Information

1. The Contractor shall use an FDCC compliant computer when accessing information on behalf of the Federal government.

2. The Contractor shall install computer virus detection software on all computers used to access information on behalf of the Federal government. Virus detection software and virus detection signatures shall be kept current.

O. COMMONLY SECURITY CONFIGURATIONS

1. The Contractor shall ensure new systems are configured with the applicable Federal Desktop

Core Configuration (FDCC) (http://nvd.nist.gov/fdcc/index.cfm), and applicable configurations from http://checklists.nist.gov as jointly identified by the Operating Division

(OPDIV)/Staff Division (STAFFDIV) Contracting Officer’s Technical Representative

(COTR) and the Chief Information Security Officer (CISO).

2. The Contractor shall ensure hardware and software installation, operation, maintenance, update, and/or patching will not alter the configuration settings specified in: (a) the FDCC

(http://nvd.nist.gov/fdcc/index.cfm ); and (b) other applicable configuration checklists as referenced above.

3. The Contractor shall ensure applications are fully functional and operate correctly on systems configured in accordance with the above configuration requirements.

4. The Contractor shall ensure applications designed for end users run in the standard user context without requiring elevated administrative privileges.

5. Federal Information Processing Standard 201 (FIPS-201) (vii) compliant, Homeland Security

Presidential Directive 12 (HSPD-12) card readers shall: (a) be included with the purchase of http://www.sans.org/top20/?ref=3706#w1 http://nvd.nist.gov/fdcc/index.cfm http://checklists.nist.gov/ http://nvd.nist.gov/fdcc/index.cfm

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 12 servers, desktops, and laptops; and (b) comply with FAR Subpart 4.13, Personal Identity

Verification.

6. The Contractor shall ensure all its subcontractors which perform work under this contract (at all tiers) comply with the above requirements.

P. SPECIAL INFORMATION SECURITY REQUIREMENTS FOR FOREIGN

CONTRACTORS/SUBCONTRACTORS

When foreign contractors/subcontractors perform work under this acquisition at non-US

Federal Government facilities, provisions of HSPD-12 do NOT apply.

Q. REFERENCES: INFORMATION SECURITY INCLUDING PERSONALLY

IDENTIFIABLE INFORMATION

(1) Federal Information Security Management Act of 2002 (FISMA), Title III, E-

Government Act of 2002, Pub. L. No. 107-347 (Dec. 17, 2002);

http://csrc.nist.gov/drivers/documents/FISMA-final.pdf

(2) DHHS Personnel Security/Suitability Handbook:

http://www.knownet.hhs.gov/acquisition/pssh.pdf

(3) NIH Computer Security Awareness Course: http://irtsectraining.nih.gov/

(4) NIST Special Publication 800-16, Information Technology Security Training

Requirements: http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf

Appendix A-D: http://csrc.nist.gov/publications/nistpubs/800-16/AppendixA-D.pdf

(5) NIST SP 800-18, Guide for Developing Security Plans for Information Technology

Systems: http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf

(6) NIST SP 800-53, Revision 1, Recommended Security Controls for Federal

Information Systems: http://www.csrc.nist.gov/publications/drafts/800-53-rev1-ipd-clean.pdf

(7) NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, Volume I: http://csrc.nist.gov/publications/nistpubs/800-

60/SP800-60V1-final.pdf; Volume II, Appendices to Guide For Mapping Types of

Information and Information Systems To Security Categories, Appendix C at:

http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf and Appendix

D at: http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf.

(8) NIST SP 800-64, Security Considerations in the Information System Development

Life Cycle: http://csrc.nist.gov/publications/nistpubs/800-64/NIST-SP800-64.pdf

(9) FIPS PUB 199, Standards for Security Categorization of Federal Information and

Information Systems:

http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://www.knownet.hhs.gov/acquisition/pssh.pdf http://irtsectraining.nih.gov/ http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf http://csrc.nist.gov/publications/nistpubs/800-16/AppendixA-D.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf http://csrc.nist.gov/publications/nistpubs/800-60/SP800-60V2-final.pdf http://csrc.nist.gov/publications/nistpubs/800-64/NIST-SP800-64.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 13

(10) FIPS PUB 200, Minimum Security Requirements for Federal Information and

Information Systems: http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf

(11) OMB Memorandum M-06-15, Safeguarding Personally Identifiable Information (05-

22-06):

http://www.whitehouse.gov/omb/memoranda/fy2006/m-06-15.pdf

(12) OMB Memorandum M-06-16, Protection of Sensitive Agency Information (06-23-06):

http://www.whitehouse.gov/OMB/memoranda/fy2006/m06-16.pdf

(13) OMB Memorandum M-06-19, Reporting Incidents Involving Personally Identifiable

Information and Incorporating the Cost for Security in Agency Information

Technology Investments (07-12-06) http://www.whitehouse.gov/omb/memoranda/fy2006/m-06-19.pdf

(14) OMB Memorandum, Recommendations for Identity Theft Related Data Breach

Notification (09-20-06) http://www.whitehouse.gov/omb/memoranda/fy2006/task_force_theft_memo.pdf

(15) OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of

Personally Identifiable Information (05-22-07) http://www.whitehouse.gov/omb/memoranda/fy2007/m07-16.pdf

(16) OMB Memorandum M-07-18, Ensuring New Acquisitions Include Common Security

Configurations (06-01-07) http://www.whitehouse.gov/omb/memoranda/fy2007/m07-18.pdf

(17) Guide for Identifying Sensitive Information, including Information in Identifiable

Form, at the NIH ( 04-18-2008)

(http://irm.cit.nih.gov/security/NIH_Sensitive_Info_Guide.doc

(18) HHS OCIO Policies http://www.hhs.gov/ocio/policy/index.html#Security

(19) NIH Privacy Awareness Course: http://irtsectraining.nih.gov/

R. REFERENCES: PHYSICAL ACCESS SECURITY –

(1) HHS Information Security Program Policy:

http://intranet.hhs.gov/infosec/docs/policies_guides/ISPP/Information_Security_Progr am_Policy.pdf

(2) Homeland Security Presidential Directive/HSPD-12, Policy for a Common

Identification Standard for Federal Employees and Contractors (08-27-04):

http://www.whitehouse.gov/news/releases/2004/08/print/20040827-8.html

(3) OMB Memorandum M-05-24, Implementation of Homeland Security Presidential

Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal

Employees and Contractors (08-05-05):

http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf

(4) OMB Memorandum M-07-06, Validating and Monitoring Agency Issuance of

Personal Identity Verification Credentials (01-11-07):

http://www.whitehouse.gov/omb/memoranda/fy2007/m07-06.pdf

(5) Federal Information Processing Standards Publication (FIPS PUB) 201-1 (Updated

June 26, 2006): http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf http://www.whitehouse.gov/omb/memoranda/fy2006/m-06-15.pdf http://www.whitehouse.gov/OMB/memoranda/fy2006/m06-16.pdf http://www.whitehouse.gov/omb/memoranda/fy2006/m-06-19.pdf http://www.whitehouse.gov/omb/memoranda/fy2006/task_force_theft_memo.pdf http://www.whitehouse.gov/omb/memoranda/fy2007/m07-16.pdf http://www.whitehouse.gov/omb/memoranda/fy2007/m07-18.pdf http://irm.cit.nih.gov/security/NIH_Sensitive_Info_Guide.doc http://www.hhs.gov/ocio/policy/index.html#Security http://irtsectraining.nih.gov/ http://intranet.hhs.gov/infosec/docs/policies_guides/ISPP/Information_Security_Program_Policy.pdf http://intranet.hhs.gov/infosec/docs/policies_guides/ISPP/Information_Security_Program_Policy.pdf http://www.whitehouse.gov/news/releases/2004/08/print/20040827-8.html http://www.whitehouse.gov/omb/memoranda/fy2005/m05-24.pdf http://www.whitehouse.gov/omb/memoranda/fy2007/m07-06.pdf http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf

1/14/2011 Mutational Analysis Off-Site Laboratory Testing Page 14

(6) HHS Interim Policy: Contractual Implementation of Homeland Security Presidential

Directive (HSPD) 12, Policy for a Common Identification Standard for Federal

Employees and Contractors [Draft] http://www.hhs.gov/oamp/policies/hspd12contractguide.doc

(7) HHS Office of Security and Drug Testing, Personnel Security/Suitability Handbook

(02-01-05):

http://www.hhs.gov/oamp/policies/personnel_security_suitability_handbook.html

(8) HHSAR 307.7106, Statement of Work (SOW); HHSAR 307.7108 in new coverage as of 02-01-07: http://knownet.hhs.gov/acquisition/hhsar/Default.htm

(9) Federal Acquisition Regulation (FAR) 37.602, Performance Work Statement (PWS):

http://acquisition.gov/far/current/html/Subpart%2037_6.html#wp1074648

(10) FAR Subpart 4.13, Personal Identity Verification of Contractor Personnel:

http://acquisition.gov/far/current/html/Subpart%204_13.html#wp1074125

(11) FAR 52.204-9, Personal Identity Verification of Contractor Personnel [clause]:

http://acquisition.gov/far/current/html/52_200_206.html#wp1139617 http://www.hhs.gov/oamp/policies/hspd12contractguide.doc http://www.hhs.gov/oamp/policies/personnel_security_suitability_handbook.html http://knownet.hhs.gov/acquisition/hhsar/Default.htm http://acquisition.gov/far/current/html/Subpart%2037_6.html#wp1074648 http://acquisition.gov/far/current/html/Subpart%204_13.html#wp1074125 http://acquisition.gov/far/current/html/52_200_206.html#wp1139617

File details come from the government source that posted it. Updated .